Apple Mac OS X QuickDraw Manager buffer overflow

macos-quickdraw-manager-bo (22384) The risk level is classified as HighHigh Risk

Description:

Apple Mac OS X and Mac OS X Server are vulnerable to a buffer overflow caused by improper bounds checking in the QuickDraw Manager. By sending a specially-crafted PICT image, a remote attacker could overflow a buffer and execute arbitrary code on the system. When the file is viewed in a component of Mac OS that utilizes QuickDraw Manager, such as Safari, Mail, or Finder, the malicious code would be executed on the vulnerable system.


Consequences:

Gain Access

Remedy:

Apply Security Update 2005-008, as listed in AppleCare Knowledge Base Document 302413. See References.

References:

  • AppleCare Knowledge Base Document 302413: About Security Update 2005-008.
  • CIAC INFORMATION BULLETIN P-312: Apple Security Update 2005-008.
  • BID-14914: Apple Mac OS X Security Update 2005-008 Multiple Vulnerabilities
  • CVE-2005-2744: Buffer overflow in QuickDraw Manager for Apple OS X 10.3.9 and 10.4.2, as used by applications such as Safari, Mail, and Finder, allows remote attackers to execute arbitrary code via a crafted PICT file.
  • SA16920: Mac OS X Security Update Fixes Multiple Vulnerabilities
  • SECTRACK ID: 1014961: Apple QuickDraw Manager Buffer Overflow in Processing PICT Images Lets Remote Users Execute Arbitrary Code
  • US-CERT VU#529945: Apple Mac OS X QuickDraw Manager fails to properly handle corrupt PICT files

Platforms Affected:

  • Apple Mac OS X 10.3.9
  • Apple Mac OS X 10.4.2
  • Apple Mac OS X Server 10.3.9
  • Apple Mac OS X Server 10.4.2

Reported:

Sep 23, 2005

The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

For corrections or additions please email xforce@iss.net

Return to the main page